Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

user friendly

  linuxpromagazine.com » Online » News » Honeytrap 1.0.0 Released  

Print this page. Recommend
Slashdot it! Delicious Digg

Honeytrap 1.0.0 Released

Version 1.0.0 of the honeypot daemon Honeytrap has been released. It has a completely reworked configuration mechanism and new plugins.

The GPL'd program registers attacks against TCP services. When a request arrives from an unknown port, Honeytrap dynamically launches a server process to handle it. This avoids the need for the software to continually bind thousands of ports. Connection monitors based on Libpcap, Netfilter/Iptables or Netfilter_Queue handle the bindings. Honeytrap will run in various modes, including a proxy mode where it forwards connections and sniffs traffic. The daemon comprises two parts. The program core collects data and can load plugins at runtime for analysis purposes. Plugins currently available store strings and malware from attacks, and special extensions are available for identifying FTP and TFTP commands. In addition to this, there is a parser for attacks on VNC servers, a pluging that decodes Base 64 encoded exploits, and a module that identifies attacks heuristically using similarity checks. Honeytrap 1.0.0 is available as a source code archive on the Sourceforge download servers. The subversion repository for the project also supports access to the current sources. In addition to this, the download page has Xen templates and Qemu images for the virtual Honeytrap server.

(Mathias Huber)

Comments


Print this page. Recommend
Slashdot it! Delicious Digg
No More Downloads!

Save the download and take Linux Magazine DVDs instead.

Each DVD contains a full distro like Ubuntu, SUSE, Mandriva, Fedora, or Debian and comes with the corresponding issue of Linux Magazine.

Don't waste time downloading Linux!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]